American law does not ask you to obtain consent before capturing a lead. It asks you to tell people what you are doing at the moment you do it, and it forbids collection where you have not. The regulation is blunt: “If a business does not give the Notice at Collection to the consumer at or before the point of collection of their personal information, the business shall not collect personal information from the consumer.”
That is a different obligation from the European one, and companies arriving from that direction tend to build the wrong thing. They install a consent banner they may not need, and skip a notice they do need, positioned exactly where their form is.
The rules below are California’s, which matters for two reasons. They are the most developed, and they reach any business meeting the thresholds that collects information from California residents, wherever that business sits.
Notice at collection, not consent before collection
The structure of the obligation is worth understanding before the detail, because it explains why a cookie banner is not the answer to a form.
What the statute requires. A business controlling collection must, “at or before the point of collection”, inform consumers of the categories of personal information collected and the purposes, whether it is sold or shared, and “the length of time the business intends to retain each category”.
Why the notice exists, in the regulator’s words. To give consumers “timely notice, at or before the point of collection … so that consumers have a tool to exercise meaningful control over the business’s use of their personal information.”
And the consequence of omitting it is absolute. No notice, no collection. Not a warning, not a remediation period. The regulation says the business “shall not collect”.
The regulations address web forms specifically. A business collecting through a webform “may post a conspicuous link to the notice in close proximity to the fields in which the consumer inputs their personal information, or in close proximity to the button by which the consumer submits their personal information.”
Which locates the obligation precisely. Next to the field, or next to the button. Not in a footer, not behind a banner that appeared on arrival, not in a cookie preference centre.
One exception is worth flagging, because it is the only federal consent regime. Children’s online privacy law requires “verifiable parental consent” before collecting personal information from a child under 13. That is the exception that proves the general rule.
This is a short list, and most lead forms carry none of it.
The categories of personal information collected, written so as to give “a meaningful understanding of the information being collected”.
The purposes for which each category is collected and used.
Whether each category is sold or shared. Read the next section before answering this one, because the definitions are wider than the words suggest.
The retention period, or “the criteria used to determine the period of time it will be retained”. This is the element almost nobody has, because almost nobody has decided.
A link to the opt-out notice, if you sell or share.
A link to your privacy policy.
And one trap that voids an otherwise reasonable implementation. You may satisfy the notice with a link, but only “a link that takes the consumer directly to the specific section” containing those items. Directing them “to the beginning of the privacy policy … so that the consumer is required to scroll through other information … does not satisfy this standard.”
Which means the common pattern fails. A checkbox saying “I agree to the privacy policy” with a link to the top of that policy is not a notice at collection. An anchor link to the right section is.
Six items, one of which most companies have never decided. And a link to the top of your privacy policy does not count. Source : 11 CCR 7012(e) and 7012(f) (2026)
Your pixel is probably a “share”
This is the finding that changes what most B2B sites have to disclose, and it turns on two statutory definitions that are much wider than their everyday meanings.
“Sell” is not limited to money. It means disclosing personal information to a third party “for monetary or other valuable consideration.”
And “share” does not involve consideration at all. It means disclosing personal information to a third party “for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged.”
Cross-context behavioral advertising is defined too. Targeting based on information “obtained from the consumer’s activity across businesses, distinctly branded internet websites, applications, or services, other than” your own.
Put those together and the ordinary marketing stack is in scope. An advertising pixel that sends visitor data to a platform for retargeting is a disclosure to a third party for cross-context behavioural advertising. No invoice, no payment, still a share.
A state attorney general reached exactly that conclusion. In a 2022 settlement, the finding was that the company’s “arrangement with these companies constituted a sale of consumer information under the CCPA, and it triggered certain basic obligations, such as telling consumers that they are selling their information and allowing consumers to opt-out … Sephora did neither.” The penalty was $1.2 million.
Which answers element three of your notice. If you run retargeting pixels, the honest answer to “is this shared” is yes, and the opt-out obligations follow from it.
If you sell or share, a browser-level signal is not optional, and this is where recent enforcement has concentrated.
The regulator’s position. The Global Privacy Control “is one option for consumers who want to submit requests to opt-out of the sale or sharing of personal information via a user-enabled global privacy control. Under law, it must be honored by covered businesses as a valid consumer request.”
The regulation behind it. A business that sells or shares “shall process any opt-out preference signal that meets the following requirements as a valid request to opt-out of sale/sharing”, where the signal is in a commonly used format and its purpose is made clear to the consumer.
And it applies to the browser, not just the person. The signal is treated as a valid opt-out “for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles.”
There is an upside worth knowing. The homepage “Do Not Sell or Share My Personal Information” link is not required if you honour the universal signal instead. Processing the signal properly can replace the link.
Enforcement here is real and recent. A 2025 fine of $632,500 concerned excessive verification demands before an opt-out. Another, $345,178, concerned “a failure to process consumer requests to opt out of the sale or sharing of personal information for 40 days”. A 2025 settlement of $1.55 million concerned failing to let consumers opt out of targeted advertising. And a February 2026 settlement of $2.75 million concerned “failing to fully effectuate consumers’ requests to opt-out … across all devices and streaming services.”
With one sentence worth pinning above your consent tool. From the enforcement division: “Using a consent management platform doesn’t get you off the hook for compliance.”
A short notice adjacent to the submit button. What you collect, why, whether it is shared, how long you keep it, and two links: one to the opt-out notice if you share, one to your privacy policy.
With the privacy policy link pointing at the section, not the top. An anchor. This is a five-minute change and it is the difference between satisfying the standard and not.
A retention answer you have actually decided. “Until you ask us to delete it” is not a period. “Three years from last contact, then deleted” is. You need one either way, because the notice has to state it.
An honest answer on sharing. If a retargeting pixel fires on the thank-you page, you share. Say so, and provide the opt-out route that follows.
A signal handler that works before the tags fire. Whatever tool you use, verify that an incoming universal opt-out signal actually suppresses the pixels rather than being recorded and ignored. That gap is what the fines above describe.
And test it yourself. Submit the form with the signal on and watch the network requests. Nobody else is going to do this, and it is the only way to know whether your stack does what your notice says.
Take one landing page and read it as a regulator would. Is there a notice within sight of the button? Does its link land on the right section? Does it state a retention period? Does it admit that you share?
Then check the thing behind the page. Turn on a universal opt-out signal, submit a test lead, and watch whether the advertising tags still fire. If they do, your notice is describing a system you do not have.
Neither of those tasks needs a lawyer or a platform. They need an afternoon, and they close the gap that every recent enforcement action has been about.
Do I need consent before capturing an email in the US?
No federal law requires prior consent for adult business contacts. What California law requires is a notice at or before the point of collection, and it states that without that notice the business shall not collect the information at all.
Can I just link to my privacy policy under the form?
Only if the link goes to the specific section containing the required information. The regulations state that directing the consumer to the beginning of the privacy policy, so they must scroll to find it, does not satisfy the standard.
Does placing a Meta or Google pixel count as selling data?
It can count as sharing, which carries the same obligations. The definition covers disclosure for cross-context behavioral advertising 'whether or not for monetary or other valuable consideration, including transactions ... in which no money is exchanged'.
Does using a consent management platform make me compliant?
No. A California enforcement official put it directly: 'Using a consent management platform doesn't get you off the hook for compliance.' One company was fined after its privacy portal failed to process opt-outs for 40 days.